loader from loading.io

7MS #735: Baby's First Cloudflare Tunnel

7 Minute Security

Release Date: 08/14/2026

7MS #739: Tales of Pentest Pwnage – Part 89 show art 7MS #739: Tales of Pentest Pwnage – Part 89

7 Minute Security

Hey friends! Today is a tale of pentest pwnage episode, and this one features a path to escalation I have never seen before – one I could only find few references on the entire Internet. It happened completely by accident, but during the report readout I’m absolutely going to say it was intentional and that I totally meant to do that. Here’s what we cover: A client that’s actually doing the things – year two or three of testing this environment, and they had buttoned up so much that I had to dig deep. Great for them, freaking frustrating for me. Why my...

info_outline
7MS #738: Baby’s First ProjectDiscovery Neo show art 7MS #738: Baby’s First ProjectDiscovery Neo

7 Minute Security

Hey friends! Today I’m talking about Baby’s First Neo — and to be crystal clear, I don’t mean Keanu, and I don’t mean the R&B guy with the hat. I mean the AI-powered pentest assistant from our pals at . Also to be crystal clear: this is not a sponsorship, ad, partnership or anything of the sort. Just me sharing a thing I like so you can decide if you like it too. Here’s what we get into: Why I didn’t renew my ProjectDiscovery cloud subscription after a full year of running it side-by-side with Nessus — including the three things that ground my...

info_outline
7MS #737: Tales of Pentest Pwnage – Part 88 show art 7MS #737: Tales of Pentest Pwnage – Part 88

7 Minute Security

Hello friends! Today’s tale of pentest pwnage isn’t a start-to-finish march to DA – it’s me finally emptying out the backlog of “gosh, I’ve got to share this next time” internal network tips that have been rattling around in my head. Here’s what we get into: Don’t skip the boring stuff. Even when I’m testing the same network for the third or fourth time, I’ve got an ever-growing list of things I check every single time – because config drift has a nasty habit of quietly reintroducing problems that were fixed years ago. Get a second opinion on...

info_outline
7MS #736: Securing Your Family During and After a Disaster – Part 9 show art 7MS #736: Securing Your Family During and After a Disaster – Part 9

7 Minute Security

Hey friends! Today’s another slice of our Securing Your Family During and After a Disaster miniseries, and fair warning — it’s a bit of a Friday mood-ruiner. It’s been almost two months since my dad passed, and we’ve moved into a phase nobody prepared me for. Here’s what we get into: The paperwork nobody thinks about — my mom still doesn’t know what her monthly income looks like now, and the answer is buried in a box somebody lost the key to. Divvying up a lifetime of stuff — and why our 2019 house fire completely rewired how I think about possessions....

info_outline
7MS #735: Baby's First Cloudflare Tunnel show art 7MS #735: Baby's First Cloudflare Tunnel

7 Minute Security

Hey friends! Today’s episode has a new-to-me toy up front and some podcast housekeeping on the back half – all recorded with a raging case of the anxious parent giggidies, because my son Atticus had a big audition and I was minutes away from finding out whether we were doing tears of joy or tears of sadness. Baby’s first Cloudflare Tunnel Not a sponsor, not an ad – just a thing I’d heard about for years and finally had a reason to use. Here’s what we get into: The problem that sent me down this road: I wanted push-button status pages for clients that pull from one source...

info_outline
7MS #734: Insight Recon show art 7MS #734: Insight Recon

7 Minute Security

Hey friends! Today’s episode is a two-parter: some security stuff up front, and then a big ol’ personal celebration on the back half. If you’re strictly here for the security bits, I love you and you’re free to bail after the first half. If you’re here for both, God bless you. Part 1: Kicking the tires on Insight Recon What it is:  is an Active Directory security assessment tool out of Heath Adams’ new venture, . I signed up for early access a while back, finally got a login, and took it for a spin this week in my  lab. Not a sponsor, not an ad — just a...

info_outline
7MS #733: Tales of Pentest Pwnage – Part 87 show art 7MS #733: Tales of Pentest Pwnage – Part 87

7 Minute Security

Hey friends! Today’s episode comes to you from a parking lot in the rain, with a mint hot cocoa in hand and your host absolutely dragging his butt (D-R-A-G-G-I-N-G, not D-R-A-G-O-N – I’ve never seen a dragon’s butt and can’t speak to how mine compares). I’ve had a bunch of internals back to back lately and I’m basically a drooling dog who found a frisbee and refuses to put it down. Sleep be darned. So instead of walking through one test start to finish, I want to share a few things that have helped me claw out a foothold in environments that are otherwise really locked...

info_outline
7MS #732: Tales of Pentest Pwnage – Part 86 show art 7MS #732: Tales of Pentest Pwnage – Part 86

7 Minute Security

Hey friends! Welcome back to another Tales of Pentest Pwnage — my favorite mini-series where I share the good, the bad, and the “why didn’t I check THAT first?!” moments from real-world engagements. Today’s story has a little bit of everything: a legit path to domain admin, some late-night rabbit holes, a lesson in humility, and a villain you’ve definitely met before. (Spoiler: it’s DNS.) A couple of quick plugs before we dive in: Private GOAD training is going strong! — We just wrapped a 3-day private session (7 students — that’s max capacity!) of our Active...

info_outline
7MS #731: CARTP – Cloud Red Team Tactics for Attacking and Defending Azure – THE FINAL CHAPTER! show art 7MS #731: CARTP – Cloud Red Team Tactics for Attacking and Defending Azure – THE FINAL CHAPTER!

7 Minute Security

Hey friends! Fair warning: today’s episode is a bit of an emotional rollercoaster — we’ve got a big security win, some honest lab feedback, and a very personal share about my dad’s funeral. Buckle up.  certified, baby! — I’m officially a , courtesy of the folks at . It’s been a long time coming (I originally signed up for the live version and fell off after missing a couple Saturdays), but I came back for the self-paced 30-day version and finally finished the job. The lab experience — the good: — ~25 objectives, a solid lab guide, and a really fun...

info_outline
7MS #730: Baby’s First Project Swarm show art 7MS #730: Baby’s First Project Swarm

7 Minute Security

Hey friends! Still your grieving pal over here, but also your swarming friend and Protecting My Network Edge host — because this week I’ve been tinkering with something called  and I’ve got my diapers on regarding it, but I really, really like what I see so far. Then, fair warning, I flip on the tangent light and verbally barf up some personal stuff at the end. I’ll make the hand-off super clear, so if you want your free security podcast to do exactly what you want and nothing else — totally fair, and you won’t offend me by hopping off. Here’s what we cover: ...

info_outline
 
More Episodes

Hey friends! Today’s episode has a new-to-me toy up front and some podcast housekeeping on the back half – all recorded with a raging case of the anxious parent giggidies, because my son Atticus had a big audition and I was minutes away from finding out whether we were doing tears of joy or tears of sadness.

Baby’s first Cloudflare Tunnel

Not a sponsor, not an ad – just a thing I’d heard about for years and finally had a reason to use. Here’s what we get into:

  • The problem that sent me down this road: I wanted push-button status pages for clients that pull from one source of truth – not just “is the box up,” but actual narrative on where a project is at
  • Why the off-the-shelf status page tools weren’t the right shape, and why “just stick it on a web server” was a non-starter for a scraper-and-AI-slop-crawler internet
  • The auth paths I tried and abandoned before Cloudflare Tunnels entered the chat
  • How Cloudflare Access one-time PINs put a guard out front – and what happens when fartface@meowmix.com tries to log in
  • My Chick-fil-A-order-tracker dreams for multi-phase assessments, and why I think it could kill a bunch of clogged-up email threads
  • Why the code isn’t public yet (it’s public-facing infrastructure I haven’t hardened, and I’ve got hunches about where the holes are) – but reach out if you want to build something similar and I’m happy to share privately
  • Where tunnels fit generally: when something genuinely needs to be reachable, but you’d rather not hand it a public IP or expose RDP to the whole internet. It doesn’t replace Twingate for me, but it fills a different slot nicely
  • Bonus tangent: why Claude has become my long-drive road companion, and five enlightening minutes I spent learning how water towers work

Housekeeping: a refreshed jingle and a brand new bumper

  • A quick history of the 7MS jingle – from just me and an acoustic guitar, to a Fiverr band, to now
  • Why “security is hard, so let’s assume we’re probably going to get pwned by noon” has aged frighteningly well (see also: AI agents teaching each other to find previously unknown vulns)
  • Meet Jacob Davis, the guitar teacher the algorithm dropped in my lap, who recorded a gorgeous all-strings arrangement of the jingle and about 45 seconds of fingerpicking diddly goodness for our new outro bumper. Stick around to the end and give it a listen – and if you’re in the market for internet guitar lessons, he rules

And over on 7MinSec.club this week

  • I show off VoiceInk, a private, local voice dictation utility for Mac that Paul the Unstoppable turned me on to. Lifetime license, no subscription, and it does a great job on live dictation or audio files you feed it. Catch the TuesdayTOOLSday over at 7MinSec.club

Thanks for listening – to the security stuff, the tangents, or both. Come find us at 7MinSec.com, subscribe (free or paid) over at 7MinSec.club, and dig through our notes at 7MinSec.wiki. God bless you, and have a great week!